CVE-2012-6129
- EPSS 2.68%
- Veröffentlicht 03.04.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol ...
- EPSS 0.4%
- Veröffentlicht 25.03.2013 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the ...
CVE-2012-1568
- EPSS 0.05%
- Veröffentlicht 01.03.2013 05:40:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for contex...
CVE-2012-3363
- EPSS 60.48%
- Veröffentlicht 13.02.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE...
CVE-2012-6075
- EPSS 8.88%
- Veröffentlicht 13.02.2013 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly ex...
CVE-2013-0170
- EPSS 20.22%
- Veröffentlicht 08.02.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (c...
CVE-2012-5656
- EPSS 0.05%
- Veröffentlicht 18.01.2013 11:48:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
- EPSS 13.97%
- Veröffentlicht 28.12.2012 11:48:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
CVE-2012-3354
- EPSS 0.55%
- Veröffentlicht 20.11.2012 00:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.
CVE-2012-4406
- EPSS 7.79%
- Veröffentlicht 22.10.2012 23:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.